SAP Security Note
High priority
SAP security note 1600079, "FIN-FSCM-TRM-TM: Potential Directory Traversal", is a program error note released on August 9, 2011. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
Potential directory traversal in FIN-FSCM-TRM-TM. This vulnerability allows a malicious user to potentially read or write arbitrary files on the remote server, which could lead to the disclosure of confidential information or corruption of data.
Solution
Apply the corrections from SAP Security Note 1497003 as a prerequisite. Implement the corrections specified in Note 1600079.
Recommendations:
- Structure directories to reflect user and/or program names to securely separate data created by different users and programs.
- Use logical file names that correspond to the directory structure for enhanced security.
Reason and prerequisites
The affected programs contain vulnerabilities that could allow arbitrary file read/write operations by a malicious user. These could lead to disclosure of confidential information or alteration of system behavior.
CVSS
Score 0
References
Affected components
- EA-FINSERV: 604, 605
Full note on SAP: SAP Support Launchpad note 1600079
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
